Data & infrastructure
-
EU e-Evidence rules take effect
EU authorities can now send cross-border electronic evidence orders directly to service providers under a regime carrying strict production deadlines and material compliance obligations.
-
Hijacked WordPress sites powered malware network
Check Point says thousands of compromised WordPress sites were repurposed as infrastructure for a malware operation combining data theft, encryption, command and control, and stolen-data storage.
-
Alleged Azure dumps expose cloud identity gap
Alleged Azure and Entra datasets linked to some of the world’s largest companies show how credential theft outside the cloud perimeter can become access inside it without any cloud zero-day.
-
RingCentral breach data reaches 1.6m addresses
A dataset attributed to RingCentral’s July social-engineering incident contains almost 1.6 million unique email addresses, extending the known public footprint of the breach.
-
Trivy emerges as source of 2,500-org exposure
New analysis indicates that most organisations in a 2,500-plus exposure dataset were caught through the earlier Trivy compromise rather than the short-lived malicious LiteLLM releases.
-
Beacon breach reaches sensitive charity records
A UK charity has confirmed that records potentially copied from the Beacon CRM breach include medical and financial information, widening the downstream consequences of the supplier incident.
-
Threema outage exposes hosting split
A sustained DDoS campaign disrupted Threema and its colocation provider, while customers running the messaging platform on their own infrastructure remained available.
-
Fortinet patches two authentication weaknesses
Fortinet has fixed separate authentication weaknesses in FortiWeb and FortiManager, including a configuration-dependent FortiWeb administrator bypass and a FortiManager device-impersonation flaw.
-
Ivanti fixes remotely reachable Endpoint Manager flaws
Ivanti has patched three high-severity Endpoint Manager vulnerabilities, including an unauthenticated agent denial-of-service flaw and a credential exposure requiring a man-in-the-middle position.
-
Adobe patches critical Commerce authorisation flaw
Adobe has fixed a critical unauthenticated authorisation vulnerability in Commerce and Magento Open Source that can allow privilege escalation without administrator access or user interaction.








